US2024422137A1PendingUtilityA1

Decrypting synthetic transactions with beacon packets

Assignee: NETSCOUT SYSTEMS INCPriority: Aug 19, 2020Filed: Aug 26, 2024Published: Dec 19, 2024
Est. expiryAug 19, 2040(~14.1 yrs left)· nominal 20-yr term from priority
H04L 43/12H04L 69/22H04L 9/0894H04L 63/0428H04L 63/166H04L 43/10H04L 63/126H04L 9/0819
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Decrypting synthetic transactions with beacon packets is provided. A probe receives, from a client device, a start beacon packet that identifies a test of a service provided by one or more servers. The probe establishes, responsive to receipt of the start beacon packet, a log for the test. The probe stores, in the log established responsive to the start beacon packet, data packets transmitted between the client device and the one or more servers subsequent to the start beacon packet and encrypted with a key using a security protocol. The probe receives, from the client device, key information used to decrypt the data packets of the test encrypted with the key using the security protocol. The probe provides at least one of the data packets for evaluation or decryption using the key information to determine a performance of the service.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system, comprising:
 one or more processors, coupled with memory, to:   identify a start beacon packet for a test of a service, the service provided by one or more servers remote from the one or more processors;   establish, in the memory and responsive to the start beacon packet, a log file for the test of the service;   identify, for the test, a plurality of data packets transmitted between the one or more processors and the one or more servers subsequent to the start beacon packet, wherein at least a portion of the plurality of data packets are encrypted;   store, in the log file, decrypted data corresponding to the plurality of data packets;   identify a stop beacon packet that indicates completion of the test; and   release, responsive to the stop beacon packet, the log file to determine a performance of the service.   
     
     
         2 . The system of  claim 1 , comprising:
 the one or more processors to execute a probe, wherein the probe receives the start beacon packet for the test of the service and establishes the log file.   
     
     
         3 . The system of  claim 2 , wherein the probe comprises a loopback interface corresponding to a physical interface communicatively coupled with the one or more processors, wherein the one or more processors transmit the decrypted data to the loopback interface of the probe. 
     
     
         4 . The system of  claim 2 , wherein a client device comprises the one or more processors, coupled with memory. 
     
     
         5 . The system of  claim 1 , comprising the one or more processors to:
 identify key information used to encrypt the plurality of data packets; and   generate the decrypted data using the key information.   
     
     
         6 . The system of  claim 1 , wherein the start beacon packet comprises a source internet protocol “IP” address, and the one or more processors are further configured to:
 parse a header of a first data packet of the plurality of data packets to identify a first source IP address of the first data packet; 
 determine the first source IP address of the first data packet corresponds to the source IP address indicated in the start beacon packet; and 
 store, responsive to the first source IP address corresponding to the source IP address, the first data packet in the log file. 
 
     
     
         7 . The system of  claim 1 , comprising the one or more processors to:
 provide a terminating proxy configured to establish a communication channel between the one or more processors and the one or more servers via the terminating proxy.   
     
     
         8 . The system of  claim 7 , wherein the terminating proxy is configured to access the decrypted data corresponding to the plurality of data packets for the test. 
     
     
         9 . The system of  claim 7 , wherein the terminating proxy provides the decrypted data for storage in the log file. 
     
     
         10 . The system of  claim 1 , comprising:
 a terminating proxy, executed by the one or more processors, to provide decrypted application data corresponding to the plurality of data packets; and   the one or more processors to inject the decrypted application data into a payload of the plurality of data packets to generate the decrypted data corresponding to the plurality of data packets.   
     
     
         11 . The system of  claim 10 , comprising:
 the one or more processors to pad the decrypted data to account for differences in packet sizes or sequence numbers between the decrypted application data and the plurality of data packets.   
     
     
         12 . A method, comprising:
 identifying, by one or more processors, coupled with memory, a start beacon packet for a test of a service, the service provided by one or more servers remote from the one or more processors;   establishing, by the one or more processors, in the memory and responsive to the start beacon packet, a log file for the test of the service;   identifying, by the one or more processors, for the test, a plurality of data packets transmitted between the one or more processors and the one or more servers subsequent to the start beacon packet, wherein at least a portion of the plurality of data packets are encrypted;   storing, by the one or more processors, in the log file, decrypted data corresponding to the plurality of data packets;   identifying, by the one or more processors, a stop beacon packet that indicates completion of the test; and   releasing, by the one or more processors, responsive to the stop beacon packet, the log file to determine a performance of the service.   
     
     
         13 . The method of  claim 12 , comprising:
 executing, by the one or more processors, a probe, wherein the probe receives the start beacon packet for the test of the service and establishes the log file.   
     
     
         14 . The method of  claim 13 , wherein the probe comprises a loopback interface corresponding to a physical interface communicatively coupled with the one or more processors, the method comprising:
 transmitting, by the one or more processors, the decrypted data to the loopback interface of the probe.   
     
     
         15 . The method of  claim 12 , wherein the start beacon packet comprises a source internet protocol “IP” address, comprising:
 parsing, by the one or more processors, a header of a first data packet of the plurality of data packets to identify a first source IP address of the first data packet; 
 determining, by the one or more processors, the first source IP address of the first data packet corresponds to the source IP address indicated in the start beacon packet; and 
 storing, by the one or more processors, responsive to the first source IP address corresponding to the source IP address, the first data packet in the log file. 
 
     
     
         16 . The method of  claim 12 , comprising:
 providing, by the one or more processors, a terminating proxy configured to establish a communication channel between the one or more processors and the one or more servers via the terminating proxy.   
     
     
         17 . The method of  claim 16 , comprising:
 accessing, by the terminating proxy, the decrypted data corresponding to the plurality of data packets for the test; and   providing, by the terminating proxy, the decrypted data for storage in the log file.   
     
     
         18 . The method of  claim 12 , comprising:
 providing, by the one or more processors, a terminating proxy;   accessing, by the terminating proxy, decrypted application data corresponding to the plurality of data packets;   providing, by the terminating proxy, the decrypted application data;   injecting, by the one or more processors, the decrypted application data into a payload of the plurality of data packets to generate the decrypted data corresponding to the plurality of data packets.   
     
     
         19 . The method of  claim 18 , comprising:
 padding, by the one or more processors, the decrypted data to account for differences in packet sizes or sequence numbers between the decrypted application data and the plurality of data packets.   
     
     
         20 . A non-transitory computer readable storage medium storing processor executable instructions that, when executed by one or more processors, cause the one or more processors to:
 identify a start beacon packet for a test of a service, the service provided by one or more servers remote from the one or more processors;   establish, in the memory and responsive to the start beacon packet, a log file for the test of the service;   identify, for the test, a plurality of data packets transmitted between the one or more processors and the one or more servers subsequent to the start beacon packet, wherein at least a portion of the plurality of data packets are encrypted;   store, in the log file, decrypted data corresponding to the plurality of data packets;   identify a stop beacon packet that indicates completion of the test; and   release, responsive to the stop beacon packet, the log file to determine a performance of the service.

Join the waitlist — get patent alerts

Track US2024422137A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.